THE LEGAL DEPARTMENT AS AN ESG AGENT IN THE BRAZILIAN (RE)INSURANCE MARKET

The rise of the ESG (Environmental, Social and Governance) agenda has been redefining the way the entire insurance and reinsurance market operates in Brazil, demanding a posture that transcends the mere pursuit of selling insurance products in favor of sustainable longevity. In this scenario of transformation, the legal department has been moving away both from the image of an “intensive care unit”, called upon only when a problem has already materialized, and from the position of a mere validator of processes and contracts, to become a central agent in the strategic architecture of (re)insurers. The connection between Law and sustainability is not merely formal; it is intrinsic, since the Governance pillar constitutes the backbone upon which environmental and social practices are built and overseen. In my role as executive legal manager at a Brazilian insurance company, the clear perception of this transformation is what distinguishes reactive management from a performance that effectively adds value to the company’s business. Worldwide, the insurance sector operates under the logic of long-term risk management, tied to mutualism — its fundamental pillar — making it naturally aligned with sustainability principles. Working in the legal department of an insurer requires a solid understanding of the company’s business and how its various areas operate, as well as deep technical knowledge of how the different types of insurance work. In this context, the in-house legal department acts as a kind of guardian of corporate trust, striving to ensure that risk analysis and underwriting occur within applicable legal and regulatory parameters, always aiming at the sustainability of the insurer’s operations and, ultimately, of the (re)insurance market. For this performance to be truly transformative and valuable, the composition of the legal team is a determining factor. In my view, there is a rather outdated notion that legal departments should be composed of generalist lawyers or litigation specialists (under the argument that those who handle litigation can handle anything else, being, for example, able to work in advisory roles). However, this view has been losing ground in the face of the growing demand for multidisciplinary teams. In building a high-performance team, I have been prioritizing diversity of backgrounds and specialties, bringing together professionals who understand not only the Brazilian legal system but also risk management, sustainability metrics, and who demonstrate the continuous development of soft skills, such as: clear communication, active listening to understand internal demands, the ability to mediate between areas, and collaboration skills.[1] This plurality of perspectives allows the legal department to provide technical guidance more assertively, aiming at conducting business safely and in a balanced manner. It is worth noting that intellectual diversity within a legal department is an ESG practice, enabling richer discussions both within the department and with other areas of the company. The relevance of this structure is heightened by the Brazilian regulatory environment. In Brazil, the insurance market is supervised by the Superintendence of Private Insurance (SUSEP), a regulatory body that has been proactive in implementing sustainability guidelines. In particular, Circular SUSEP No. 666/2022 establishes clear frameworks for the integration of ESG risks into the management of (re)insurers. In this context, the legal department, together with the risk and compliance team, assumes the role of guiding interpreter and implementer of the regulation in question, ensuring that the company’s board makes well-informed decisions focused on regulatory compliance or, where appropriate, on the conscious assumption of certain risks. The [1] I have already discussed this in an interview published on the Revista Roncarati website: https://legismap.com.br/conteudos/colunistas/rodrigo-filgueiras/entrevista-com-taisa-loureiro-gerente-executiva-juridica-na-fator-seguradora legal team’s technical and regulatory knowledge adds significant value by enabling the insurer to navigate well-informed and safely through a sea of regulatory requirements. As can be seen, the legal department has already positioned itself as a decision-support hub for the company’s senior executives. It has thus been moving away from being a backoffice area and has begun to act as a true strategic advisor, providing the necessary substrate for strategic decision-making. The active participation of the legal department in the daily life of the board of directors ensures that the vision of risks and opportunities is present at every step of the insurer. When the legal department is heard as a voice of strategic leadership, corporate governance is strengthened against legal and reputational challenges. Historically, many legal departments were called upon only as an “intensive care unit,” summoned to remedy problems or litigation that had already arisen. The current dynamic, however, demands that the legal team actively act as a partner to the business areas from the very first discussions and negotiations. For instance, Brazil has a new legal framework for the insurance market, Law No. 15,040/2024, which required, among other things, the adaptation of insurance policy wordings to the new rules in force. By working on the update of insurance products, in partnership with the Product, Underwriting, and Claims teams, our legal department contributed by presenting to the board a structured action plan for product adaptation, as well as identifying what needed to be changed in each product and wording that could raise questions in cases of litigated claim denials, among other issues. In the field of litigation, the legal department’s performance has also been strategically impacted. The discussion and development of defense theories, whether in the judicial or administrative sphere, in conjunction with outsourced law firms, has been incorporating elements of sustainability and the social function of contracts. Currently, it is not merely about winning a lawsuit, but about building jurisprudence favorable to the Brazilian (re)insurance market, based on theories that reflect both the technical reality of the (re)insurance market and the importance of preserving mutualism for the very longevity of the market. The in-house legal department that deeply understands the company’s business is better equipped to present outside counsel with arguments that connect legislation, market-specific regulation, and the insurer’s operational reality. This, in turn, contributes to the development of more assertive, technical, and well-founded defense theories and strategies. This sophistication in legal disputes is essential to maintain the economic and financial balance of contracts. As outlined

Democracy Reconstruction?

The question entitling these notes hints at a misunderstanding of the roots of current autocratic regimes. The “systems” of capitalism and communism have been considered by the political theory of the past century as abstractions that fail to address the fundamental problem. This difficulty is said to lie in building institutions or orderly and peaceful means for political, economic and social exchange. But, such construction was deemed to be moral in nature by the same political theory. Two keys may provide the grounds for a straightforward solution in a context where the challenge of new institutions starts with grasping the task. First, there is a reasoning on morality based on conscious individuals instead of a herd or its political equivalent of an omnipotent Volk. The ramifications of a moral focus on individuals, as opposed to an appreciation of good and evil for the community, may be spared for purposes of these notes. In the second place, lessons on the effectiveness and function of fundamental rights should be learned from by their transformation of the absolute State. The “classic” limiting function of these rights can be coupled with a moral approach to minorities to craft a twofold criterion. This criterion may replace mass-related protections for minorities not to be subdued by a supermajority or other voting exercises. At the same time the contents and scope of fundamental rights in the modern State organization may be set out generally for groups of individuals beyond the case-by-case rule of such rights’ proportionality. In conclusion, a different concept of morality enhanced with a content-providing function of fundamental rights may result in small sets of rules, especially at a non-constitutional level. The effective enforcement of these rules through prohibitions of certain governmental action may transform merely electoral democracies into an authentic legitimacy. About the Author Stephan H. Tribukait Vasconcelos, Founding Partner, Tribukait Vasconcelos, S.C. Stephan Tribukait is the founder of Tribukait Vasconcelos, S.C., established in Mexico City in 2010. With nearly 30 years of experience, he specializes in complex transactions, mergers and acquisitions, finance, and competition law. A graduate with honors from Escuela Libre de Derecho, he earned an LL.M. in International Trade Law in England in 2000. Fluent in English, German, and Spanish, Stephan advises multinational companies on cross-border transactions. He is a non-governmental advisor to the International Competition Network (ICN), a long-time member of the American Bar Association, and has taught competition law for nearly three decades while publishing extensively on competition and international trade law.

California Is Closing In on the First Binding AI Rules for Lawyers

Most states have told lawyers how they should use AI. California is close to being the first state that can actually enforce it. Senate Bill 574 passed the California Senate 39 to 0 in late January 2026 and is now working its way through the Assembly, which must pass it by August 31, the final day of the legislative session, or it dies for this session. If it clears the Assembly, it goes to Governor Gavin Newsom, who can sign it, let it become law without a signature, or veto it. If enacted, it would typically take effect the following January. What makes SB 574 different from what has come before isn’t really its content. Most of what it asks of lawyers already exists in some form as guidance from the State Bar of California. What’s different is the form. Guidance is advisory. A statute is not. What the bill actually requires Introduced by State Senator Tom Umberg, chair of the Senate Judiciary Committee, SB 574 sets duties for attorneys and arbitrators using generative AI. Stripped of the legislative language, four things stand out. First, confidentiality at the point of input. Attorneys would be prohibited from entering confidential, personal identifying, or otherwise nonpublic information into a public generative AI system. The bill does not attempt to define every edge case of what counts as confidential, but it does specify personal identifying information clearly: birthdates, Social Security numbers, driver’s license numbers, financial account numbers, addresses, and phone numbers, along with anything already sealed or protected by court order or statute. Second, personal verification. This is the provision most directly aimed at the hallucination problem. An attorney responsible for a filing would have to personally read and verify every citation in it, regardless of whether AI, a paralegal, or the attorney themselves originally produced it. Delegating the drafting is fine. Delegating the verification is not. Third, protection against bias. The bill includes language intended to prevent generative AI use from producing discriminatory or unlawfully biased outcomes, an obligation that sits alongside existing anti-discrimination duties rather than replacing them. Fourth, disclosure consideration. Attorneys would need to consider whether disclosing AI use is appropriate when generative AI is used to create public-facing content, though this provision is framed as a duty to consider rather than a blanket disclosure mandate. The bill also reaches beyond lawyers to arbitrators, who would be barred from delegating actual decision-making to a generative AI tool. An arbitrator can use AI as an aid. The independent analysis of facts and law has to remain the arbitrator’s own. Why this is happening now SB 574 didn’t emerge from nowhere. It’s a direct legislative response to a problem that has been building in courtrooms across the country for three years: AI systems producing fabricated case citations, invented quotations, and misstated holdings, some of which have made it past the attorney who signed the filing and into the official court record. The scale of the problem is no longer a handful of embarrassing anecdotes. Researchers tracking the issue have documented well over a thousand US court proceedings in which a party relied on AI-hallucinated material and a court responded, with sanctions escalating sharply since the first widely reported case in 2023. Several federal appellate courts have noted publicly that warnings and reprimands alone have not slowed the trend. California’s own State Bar has been working a parallel, related track. Its ethics committee, COPRAC, separately proposed folding AI-specific obligations directly into the state’s formal Rules of Professional Conduct, rather than keeping them in a non-binding practical guidance document. That rule-amendment process and SB 574 are distinct efforts moving on separate timelines, one through the bar’s rulemaking process and one through the legislature, but they point in the same direction: California moving AI obligations from advisory to enforceable. What it would mean in practice For law firm partners and litigators, the personal verification requirement is the one to plan around. It doesn’t ban AI-assisted drafting or research. It does mean the attorney who signs a filing cannot treat AI-checked as good enough; they need their own read of every citation, which has real implications for how review workflows and billing are structured, particularly on large filings. For General Counsel, the relevant question is less about internal use and more about what standard to expect from outside counsel. If California codifies personal verification as a matter of law, it becomes a reasonable baseline to ask about when engaging or auditing outside firms, in California and, over time, likely well beyond it. For legal operations and legal technology teams, the confidentiality provision is the most immediately actionable. It draws a clear line around public generative AI tools specifically, which puts pressure on firms and departments to be explicit about which tools are “public” versus private or closed instances, and to have that distinction documented rather than assumed. What happens next As of this writing, SB 574 is pending in the Assembly, working through committee review ahead of the August 31 deadline. A unanimous Senate vote signals strong support but does not guarantee passage in the Assembly, and the bill has already been amended once since its introduction in response to feedback from practitioners and legal educators. We’ll be tracking where it lands. California has a track record of setting standards that other states eventually adopt in some form, from privacy law to AI regulation more broadly. Whether or not SB 574 becomes law this session, it’s a reasonable preview of where the rest of the profession is headed on AI accountability. Worth knowing now, not after it’s already the rule in your state. This article reflects the status of SB 574 as of the publication date noted below. Legislative status can change quickly; readers should confirm current status before relying on this piece for compliance purposes.

The Future of work for General Counsels: Designing an Agentic Legal Ops and the Rise of a new GRC Framework

The Legacy Industry Bottleneck The legal technology revolution has been engineered by and designed for the tech industries, like software companies, financial services platforms, and data-native enterprises. But what happens when cutting-edge artificial intelligence collides with asset-heavy sectors governed by layers of complex regulations, entrenched bureaucracy, and high-stakes physical and judicial liabilities? The answer, for most legal departments in these sectors, has been a painful paradox: extraordinary pressure to adopt AI, coupled with structural conditions that resist it. Legacy industries carry an enormous volume of legal obligations, municipal permits, environmental licenses, zoning disputes, supply chain contracts, social housing compliance frameworks and a production site that is mostly physical. In that scenario, basic automation tools are facing difficulties, but the pressure to pivot is coming. The thesis here is both urgent and actionable: to survive the next decade, General Counsels in traditional, asset-heavy industries must move decisively beyond basic automation and embrace what I am calling “Agentic Legal Ops”. This shift will require not just the creation of agents and orchestration, but the adaptation of the logic in our model of GRC (Governance, Risk, and Compliance). Yet the technology alone is insufficient. Sustainable success demands a parallel commitment to a human-centric leadership model that embraces cultural transformation. The Rise of Agentic Legal Ops There is a critical, misunderstood distinction at the heart of this conversation: the difference between automation and autonomy. Automation, in the legal context, refers to rules-based tools that execute predefined tasks when triggered by specific conditions. A system that auto-populates a contract template when a deal stage advances in a CRM; a workflow that routes an NDA to the correct approver based on deal value; a dashboard that flags regulatory deadlines on a calendar. These tools have genuine value. But they are reactive, brittle, and fundamentally dependent on humans to define every fork in the road. Agentic AI, by contrast, refers to systems capable of executing complex, multi-step workflows with a degree of autonomy. Advanced AI extensions are transforming modern Legal Operations by moving far beyond a simple “question-and-answer” function to execute complex, contextual tasks directly within a professional’s browser workflow. Instead of just drafting standalone text, AI for litigation lawyers can now actively interface with legal platforms to streamline end-to-end tasks: it can automatically navigate and log into judicial systems like the PJe, map out open deadlines from incoming subpoenas, and draft highly localized initial petitions or responses using the firm’s pre-existing templates. Furthermore, it significantly accelerates case analysis and knowledge management by digesting entire lawsuits in minutes, instantly mapping timelines, evidence, and parties while simultaneously scanning databases or the STJ for favourable jurisprudence, summarizing lengthy depositions, and standardizing file management by auto-organizing downloads into specific client folders. For contract lawyers, an agentic legal system does not simply populate a template; it reads the incoming contract, cross-references its terms against a jurisdiction-specific regulatory database, identifies deviating clauses, scores aggregate risk exposure, proposes redlines with supporting rationale, and flags unresolved issues for attorney review. For traditional industries, this distinction is transformational as Real estate and infrastructure transactions are document-intensive by nature. A single development project may generate hundreds of contracts across suppliers, public agencies, financiers, and regulatory bodies, each subject to different governing law and compliance obligations. Agentic workflows can move the legal department from passive document storage to active risk management: continuously monitoring contract portfolios, scoring exposure against shifting municipal regulations, and triggering alerts when judicial trends in a specific jurisdiction create material risk in existing agreements. But the General Counsel who wants to implement this shift must know that the decisive shift from AI assistants to AI agents was not a matter of intelligence; it was a matter of hands. For years, large language models could reason, draft, and analyse, but remained confined to the boundaries of a conversation window, unable to act on the world beyond it. Tools changed that. They gave agents the capacity to do, not merely to advise. This is the architectural inflexion point that separates the assistant era from the agentic one. That autonomy, however, only becomes governable when agents are connected securely to corporate systems, data repositories, and specialized legal tools through APIs, enterprise connectors, or emerging interoperability standards such as the Model Context Protocol (MCP). It is this secure, structured connectivity that transforms an AI model from a sophisticated drafting aid into a genuine operational actor within the legal department. The Guardrails of Trust: Governance, Risk and Compliance The introduction of autonomous AI agents into a corporate legal framework does not eliminate risk, it changes it. General Counsels who move aggressively into agentic architectures without parallel investment in AI governance are trading known legal risks for novel, and potentially more complex, ones. The rapid integration of AI into the corporate ecosystem is fundamentally transforming the practice of GRC from a framework of static, periodic reviews into a model of dynamic, real-time oversight. A profound competence gap currently exists within boards of directors and executive committees, leaving leadership teams to navigate and govern without the tools to properly decode the risks. But this gap is not only technical, it is also linguistic. Board members and executive committees are fluent in the vocabularies of reputational, financial, and operational risk; AI risk, as it is typically presented, speaks a different dialect entirely. The strategic imperative for the General Counsel, therefore, is not simply to raise AI risk on the board agenda, but to translate it: to reframe model hallucination as reputational exposure, data governance failure as regulatory and financial liability, and over-reliance on autonomous agents as operational concentration risk. When AI risk is mapped onto the risk categories that boards already own and govern, it stops being only a technology conversation. To mitigate this extreme institutional vulnerability, GRC practices and Audit Committees must urgently step up. Modernizing corporate governance demands an immediate structural rethink of both board agendas and executive literacy. The Board of Directors must expand its standard oversight to include a new, multi-dimensional matrix that scrutinises five critical pillars:

“Clean Stadium” and Ambush Marketing: The Invisible Dispute Over Brands at the World Cup

The World Cup is not merely a football tournament. It is also one of the largest commercial assets in global sport. Behind the scenes of the matches lies a sophisticated structure of economic exploitation involving broadcasting rights, licensing, advertising, sponsorship, ticket sales, official merchandise, and intellectual property protection. Within this landscape, the “clean stadium” policy adopted by FIFA reveals a less visible, yet legally significant, dimension of the event: the attempt to control the competition’s commercial environment in order to preserve the exclusivity granted to its official sponsors. The expression “clean stadium” may sound like a reference to the physical organization of the event venue. In the context of major sporting events, however, its meaning is essentially trademark- and advertising-related. It refers to the requirement that official competition venues be delivered free of brands, advertisements, trade names, promotional activations, or visual identities belonging to companies that are not among the organizing entity’s authorized sponsors or partners. In practice, this may mean the removal, concealment, or neutralization of advertising boards, local sponsors’ names, brands in circulation areas, promotional activations, and even stadium naming rights. Thus, a venue that is known throughout the year by a company’s name may, during the World Cup, be identified by a neutral designation, generally linked to the host city. The measure seeks to prevent unauthorized brands from benefiting from the event’s global exposure without having acquired the corresponding rights. This dynamic connects directly to the concept of ambush marketing. Broadly speaking, ambush marketing occurs when a brand seeks to take advantage of the visibility, prestige, or exposure of an event without authorization to do so. The brand “rides on” the economic and symbolic value of that event, creating, whether explicitly or implicitly, an improper commercial association. In the context of major sporting events, this practice is usually divided into two main categories: (i) ambush by association and (ii) ambush by intrusion. The first occurs when a company suggests, without authorization, some connection with the event, its organizers, or its official symbols — as observed in a campaign run by 99 in Brazil, which led the CBF (Brazilian Football Confederation) to send the company a cease-and-desist notice.1 This may occur through the use of names, slogans, mascots, trophies, logos, visual identity, hashtags, or expressions capable of leading the public to believe there is sponsorship, support, or official authorization. The second occurs when a brand physically inserts itself into the event environment, displaying its products, services, or promotional elements in high-visibility locations without the organizing entity’s authorization. It is precisely in this second dimension that the “clean stadium” policy gains greater relevance. During the World Cup, the stadium is not merely a sporting venue but a global showcase. Every advertising board, stand shot, aerial view, mixed-zone interview, and every detail visible in the broadcast can generate significant advertising value. If non-sponsoring brands were to remain exposed in these environments, they could gain a commercial advantage incompatible with the exclusivity contracted for by official sponsors. 1 For more information, see https://www.infomoney.com.br/negocios/cbf-acusa-99-de-marketing-de-emboscada-apos-campanha-inspirada-em-endrick/ FIFA’s rationale, therefore, is clear: if a company paid to become an official World Cup sponsor, it expects its investment to be protected against the competing presence of brands that did not acquire the same right. The “clean stadium” policy thus functions as a preventive barrier against ambush marketing by intrusion. Even before any discussion of consumer confusion or improper association arises, the event environment is controlled to reduce the risk of parasitic exposure. FIFA’s Intellectual Property Guidelines2 help to illustrate this rationale. In its guidelines, FIFA emphasizes that it holds broad rights related to the World Cup, including intellectual property, media, marketing, licensing, ticketing, and other commercial rights. It also states that its protected assets are not limited to official names and logos, but extend to signs, symbols, slogans, visual elements, mascots, trophies, event designations, and other identifiers capable of referring to the tournament. Moreover, the entity’s guidelines make clear that the examples provided are non-exhaustive. This point is particularly important, as it shows that the analysis of a potential infringement is not limited to a formal check of whether a given logo was used. The assessment is contextual. A campaign may be problematic even without fully reproducing a registered trademark, if its overall visual language, wording, or commercial strategy suggests an unauthorized association with the World Cup. This reasoning also applies to the “clean stadium” policy. The concern is not limited to removing identical brands or direct competitors of official sponsors. The goal is to prevent the public, the press, or the global audience from being exposed to brands that could benefit from the context of the competition without authorization. For this reason, the neutralization of naming rights, however excessive it may seem from an everyday standpoint, is justified within the event’s economic rationale, and the official space should reflect only the brands authorized by FIFA. Naturally, this policy generates tensions. Many modern stadiums are built or maintained under long-term naming rights agreements. For the companies holding these rights, the temporary removal of their brand during an event with a worldwide audience can represent a significant loss of exposure. For fans and the local public, the name change may seem artificial. For creative brands, the censorship or visual adaptation of their signs can even become an opportunity for humorous communication, as seen in recent episodes involving brands that made light of their own neutralization, such as Levi’s and Gillette. These reactions show that the topic is not merely legal, but also cultural and commercial. In a digital communication environment, attempting to erase a brand can, paradoxically, generate even more attention for it. Creatively dodging the stadiums’ visual clean-up rules can create social media engagement, provided it does not cross the line between legitimate commentary and improper association. That boundary, however, is a delicate one. From the standpoint of Brazilian law, the issue also gained more relevant contours with the General Sports Law (Law No. 14,597/2023). Unlike the scenario following the 2014 World Cup, when the

Two Federations, One Question

By Matheus de Albuquerque Schulhan Vidal, Head of Legal, Paag Before a federation can regulate betting, it has to settle a prior question: who does the regulating? The center, or the units? The United States answered “the units”. Brazil answered “the center”. Most comparisons of the two markets stop there, usually with a table of tax rates attached. The more interesting fact is that neither answer held. In April 2025 a federal appeals court told New Jersey it could not enforce its gambling laws against a federally licensed exchange. Three months later a judge in Manhattan held the opposite. Brazil has spent two years watching its Supreme Court strike down state and municipal betting regimes that keep growing back. Both federations are relitigating the question they thought they had settled, from opposite ends. Fragmentation, and the federal law nobody talks about The American market is usually called mature, mostly because of physical casinos dating from the 19th century. On the other hand, legal sports betting in the United States, as it is today, only dates to 2018, when the Supreme Court struck down PASPA in Murfihy v. NCAA,1 a decision that legalized nothing, but only removed a federal prohibition on states legalizing, and handed the question to fifty legislatures. What followed was not deregulation but multiplication. Roughly thirty-nine states plus the District of Columbia now permit sports betting in some form, about thirty-two of them online. Tax rates on gross gaming revenue run from 5.75 percent in Nevada to 51 percent in New York.2 New Hampshire and Rhode Island built single-operator monopolies; New Jersey and Colorado opened competitive marketplaces. Minimum age, college-betting rules, licensing standards and enforcement powers all change at the border. 1 Murfihy v. Nat’l Collegiate Athletic Ass’n, 584 U.S. 453 (2018). 2 As of mid-2025, roughly 38 to 40 states plus the District of Columbia permit sports betting in some form, with about 32 offering statewide online wagering. Tax rates on gross gaming revenue range from 5.75 percent (Nevada and Iowa) to 51 percent (New York, New Hampshire, and Rhode Island). See Tax Found., Online Sfiorts Betting Taxes (2025), https://taxfoundation.org; state counts and rates vary by source and change frequently — confirm against state gaming-commission filings before publication. It would be wrong, though, to say there is no federal law in the US. There is. It is just the wrong kind. The Wire Act of 1951 still criminalizes the interstate transmission of wagering information, which means that in a country with thirty-nine legal markets, an operator cannot pool liquidity across state lines and must keep servers physically inside the state whose bets they process. The compliance stack duplicates at every border, and it does so not because Congress designed a federalist regulatory scheme, but because Congress passed a prohibition in 1951 and never replaced it with anything. That is the shape of the American federal presence in gambling: prohibitionary rather than regulatory. It tells states what they may not send across a wire. It says nothing about how to license an operator, what a bettor is owed, or who audits the book. Those questions went to whoever wanted them, and the answer works reasonably well against licensed operators and badly against everyone else. State regulators can audit, fine and revoke. Against an offshore book they have no reach, and no federal partner to call. Centralization, won in court Brazil went the other way, and did it in one statute. Law 14.790/2023 created a single national regime: one licensing authority (the Secretariat of Prizes and Betting, SPA, inside the Ministry of Finance), one monitoring layer (SIGAP), a mandatory .bet.br domain, and a federal concession costing R$30 million, covering up to three brands for five years.4 The architecture was not simply legislated into place. It has been enforced, decision by decision, against states and municipalities building cheaper alternatives. Rio de Janeiro’s state lottery, Loterj, licensed operators for a fraction of the federal price and let them take bets nationwide. In January 2025 Justice André Mendonça ordered it to stop and to restore geolocation controls; the full Court confirmed the injunction in February.5 In December 2025 Justice Nunes Marques suspended municipal betting laws throughout the country, an injunction that still awaits plenary referendum. More than eighty municipalities had passed such laws in three years, fifty-five of them in 2025 alone.5 3 18 U.S.C. § 1084 (2018) (the Wire Act). 4 Lei No. 14.790, de 29 de dezembro de 2023, Diário Oficial da União [D.O.U.] de 30.12.2023 (Braz.). 5 S.T.F., ACO 3595, Rel. Min. André Mendonça, liminar de 02.01.2025, referendada pelo Plenário Virtual em 28.02.2025 (Braz.). [Loterj barred from crediting ofierators for bets filaced outside Rio de fianeiro; geolocation controls reinstated.] 5 S.T.F., ADPF 1212, Rel. Min. Nunes Marques, medida cautelar de 03.12.2025 (ad referendum do Plenário) (Braz.). The decision records that roughly 55 municipalities across 17 states enacted lottery laws in 2025 alone, and more than 80 The statutory hook is Article 35-A of Law 13.755/2018, as amended: states and the Federal District may exploit only the lottery modalities set out in federal law, and only within their own territory. The Court reads that against a line of precedent (ADPFs 492 and 493, ADI 4.985) affirming the Union’s exclusive competence over lotteries.7 So Brazil’s model is a contested hierarchy that the Union keeps winning. It holds for a reason that has little to do with doctrine. Because betting settles through Pix and the .bet.br domain, the payment rail is the enforcement layer. KYC happens at cash-in and cash-out. Credit cards are prohibited outright. When the Ministry of Finance decided that welfare recipients should not be betting, it did not need a rule for operators to follow: it blocked 2.8 million beneficiaries who already held accounts, and barred the other 24 million from opening one.8 Whatever one thinks of that decision, no American state could execute it, because no American state controls the money. The inversion Here is what a static comparison misses. The federal vacuum the United States left

The Ghost in the Pipeline: Managing “Agentic AI” Liability in Corporate Workflows

By the LexTalk World Editorial Team | August 2026 | Legal Leadership & AI Governance For the past two years, the corporate conversation around Artificial Intelligence focused on experimentation. Legal departments ran pilot programs, experimented with Large Language Models (LLMs) for document summarization, and debated the ethics of generative drafting. That initial phase is officially over. As corporate legal departments head into the second half of 2026, the technology itself has fundamentally evolved. Organizations are no longer just using “assistive” AI that generates text for human review; they are deploying Agentic AI, autonomous digital systems designed to execute multi-step workflows, process financial transactions, parse vendor contracts, and make real-time operational decisions with minimal human intervention. This shift from assistance to agency introduces an unprecedented corporate challenge: The Liability Gap. When an autonomous system makes a flawed decision that leads to a regulatory breach, a financial loss, or a trade secret leak, who holds the primary fiduciary responsibility? The Failure of Passive AI Policy Most enterprise AI policies written between 2024 and 2025 were reactive. They focused primarily on employee behavior: prohibiting the entry of sensitive client data into public LLMs and requiring “human-in-the-loop” verification for drafted work. However, passive policy frameworks crumble when applied to agentic workflows. Unlike a human employee who follows an explicit chain of command, autonomous software agents operate dynamically. They pull data from multiple internal silos, interface with third-party vendor tools, and execute decisions at speeds that render real-time human oversight practically impossible. A recent consensus among senior General Counsel highlights a sobering reality: A written policy is not a legal shield. Regulators, including the FTC, SEC, and European data protection authorities, are increasingly looking past internal employee handbooks to evaluate whether an enterprise has implemented enforceable, hardcoded accountability controls. If your organization cannot demonstrate “Compliance by Design”, where legal guardrails and audit trails are built directly into the software architecture. Your board remains dangerously exposed. The Three Invisible Risks Facing In-House Teams To navigate this new era of autonomous workflows, General Counsel and Chief Legal Officers must audit three “invisible” risk vectors within their enterprise: 1. Shadow AI and Embedded Vendor Tools While a corporate legal team may have audited its primary Enterprise Resource Planning (ERP) or Contract Lifecycle Management (CLM) software, dozens of smaller SaaS vendors are silently embedding autonomous agents into their daily updates. This “Shadow AI” creates hidden data pipelines that process corporate data outside the firm’s primary security and legal compliance perimeter. 2. Explainability Under Legal Scrutiny In the event of a regulatory audit or class-action lawsuit, telling a court or an enforcement agency that “the algorithm made a complex calculation” is a fast track to strict liability. Legal leaders must demand regulator-grade explainability from their tech stack, ensuring that every automated output can be traced back to its underlying logic and data sources without forcing the firm to expose its proprietary intellectual property. 3. The “Kill-Switch” Protocol In high-stakes corporate environment, speed is a double-edged sword. When an autonomous system begins propagating an error—such as misinterpreting a cross-border trade regulation or incorrectly flagging contract compliance across thousands of supplier agreements—the damage compounds exponentially. Enterprise readiness requires clear, pre-programmed “Kill-Switch” protocols that immediately halt autonomous agents the moment anomalous activity is detected. Redefining the Boardroom Conversation The role of the General Counsel in 2026 is not to stall innovation or play the “Department of No.” Instead, elite legal leaders are acting as Growth Architects by translating complex algorithmic risks into clear, actionable boardroom choices. When presenting AI strategy to the Board of Directors, forward-thinking GCs are moving away from technical jargon and focusing on three core governance questions: Traceability: Do we have an immutable audit log for every automated decision that impacts our financial statements or regulatory obligations? Vendor Accountability: Do our software contracts clearly define liability limits when an embedded third-party AI agent fails? Fiduciary Oversight: Has the board established a clear standard of care for monitoring autonomous decision-making systems? Building the Architecture of Defensible Governance The legal industry is witnessing a permanent shift from theoretical policy to enforceable governance. As cross-border regulations become more fragmented and regulatory scrutiny intensifies, the companies that succeed will be those that integrate legal oversight directly into their technological infrastructure. Navigating this transition requires more than reading whitepapers or attending vendor demonstrations. It requires continuous, candid peer intelligence, comparing notes with fellow legal leaders who are testing these frameworks in real time. The “Ghost in the Pipeline” is only dangerous when left unmonitored. By taking back control of AI asset visibility, establishing strict kill-switch controls, and demanding regulator-grade explainability, General Counsel can transform AI governance from a reactive compliance burden into a sustainable competitive advantage. (LexTalk World brings together senior General Counsel, Chief Legal Officers, and legal innovators to dissect agentic liability, cross-border risk, and corporate strategy at our upcoming global summits and executive E-Meet roundtables.)

Digital Transformation, Labor Data and Strategic Litigation in Brazil: A Practical Matrix for Legal Innovation

Digital transformation has reached labor and employment law through a less spectacular, but far more consequential route than most public debates suggest. It is not only about replacing human work with machines or predicting the end of traditional legal practice. Its real impact lies in the way companies hire, allocate, monitor, remunerate, negotiate with and eventually dismiss workers. In Brazil, where labor relations are shaped by statutory rules, collective bargaining, intense litigation and a highly specialized Labor Court system, this transformation requires a particularly careful reading. Brazilian labor law is not a field in which technology can be assessed only by speed or visual sophistication. A platform may summarize lawsuits, classify documents, generate dashboards or automate procedural steps. These functions may be useful. But usefulness is not the same as legal transformation. The more relevant question is whether technology improves the quality of judgment, the traceability of evidence, the consistency of strategy and the ability to act before risk becomes litigation. Otherwise, one may simply be looking at a well-organized workflow with a modern interface, something valuable, but not necessarily revolutionary. The Brazilian context makes this distinction essential. Labor risk is rarely located in one document or one lawsuit. It usually emerges from the interaction between employment contracts, payroll practices, job descriptions, working-time records, collective bargaining agreements, internal policies, benefits, occupational health and safety documents, HR systems and the actual way work is performed. A serious labor analysis must therefore move across law, operations, data and evidence. This is especially true in corporate transactions. Mergers, acquisitions, spin-offs, incorporations and intragroup reorganizations have always required labor due diligence. The traditional review remains necessary: employment contracts, headcount, pending lawsuits, severance liabilities, collective bargaining agreements, succession rules and payroll exposure. In Brazil, the Consolidation of Labor Laws protects employees against changes in ownership or corporate structure that could affect their rights. But in modern transactions, this is only the beginning of the analysis. The first step is to understand the workforce architecture. Each employee must be mapped according to legal entity, workplace, actual duties, reporting line, cost center, business unit, corporate purpose of the employing company and applicable union framework. In practice, the formal employer on payroll may not fully reflect the operational reality. This matters because allocation affects union classification, collective agreements, salary floors, benefits, working-time rules, profit-sharing arrangements and potential claims involving group companies or corporate succession. The second step is the collective bargaining map. Brazil’s labor system gives central importance to collective bargaining agreements and company-level agreements. They may regulate salary floors, meal and food allowances, health plans, overtime, bank of hours, shifts, profit-sharing, union contributions, stability rules, occupational conditions and penalties for non-compliance. In a corporate transaction, transferring employees from one company to another may alter the applicable union, territorial basis, bargaining date or collective instrument. A merely formal comparison of documents is insufficient. The legal team must understand which clauses affect cost, which affect operations, which require system parameterization and which may demand negotiation before integration. The third step is the compensation and benefits matrix. Brazilian labor litigation often arises from differences that were not properly documented at the time they were created. Distinct salary bands, bonus formulas, commissions, benefits, allowances, vehicles, remote-work policies and eligibility criteria may become sensitive when employee populations are integrated. The relevant question is not simply whether differences exist. The question is whether they are legally justified, objectively documented and operationally sustainable. Equal pay risks, discrimination claims, payroll misclassification and disputes over incorporated benefits are often born from the absence of a clear explanation. The fourth step is the review of contracts and internal policies. Employment contracts, amendments, confidentiality clauses, intellectual property provisions, mobility rules, remote-work arrangements, compensation policies, expense policies, performance evaluation criteria and disciplinary procedures should be compared with actual practice. A policy that looks adequate in isolation may become fragile when read against collective bargaining obligations or payroll records. Conversely, a contractual clause may be formally valid but irrelevant if the company’s operational practice contradicts it. The fifth step is litigation analytics, or jurimetrics. In Brazil, where labor litigation is both voluminous and technically specialized, data can support better decisions in individual and collective disputes. A well-structured database can classify claims by subject, claimant profile, court, region, procedural stage, amount claimed, amount provisioned, evidence available, settlement history, judgment pattern and recurrence of factual causes. This allows companies to distinguish isolated litigation from systemic risk. For individual cases, jurimetrics can improve settlement strategy, provisioning, witness preparation and procedural prioritization. It may show, for example, that certain claims have higher exposure when specific documents are missing, when working-time records are inconsistent, or when a particular factual pattern repeats across units. It can also help identify cases in which early settlement is more rational than defensive litigation, not because of generic risk aversion, but because the data indicates a poor combination of evidence, jurisdiction, claim type and expected cost. For collective matters, the use of data is even more strategic. Union negotiations, public civil actions, mass claims and recurring disputes require a broader view than case-by-case defense. Data can reveal whether a certain claim is concentrated in one region, one job family, one manager group, one payroll item, one benefit policy or one timekeeping practice. It can also support collective bargaining by showing the financial and operational impact of different scenarios, including harmonization of benefits, changes to working-time rules, profit-sharing models and transition clauses. This is where technology may create real value. It can organize large volumes of information, extract clauses from collective instruments, compare payroll data, identify inconsistencies, group lawsuits by theme, detect recurring factual causes and generate risk dashboards that connect litigation to business decisions. But the technology must remain subordinate to legal method. A dashboard is not a legal opinion. A prediction is not a strategy. A cluster of similar lawsuits is not, by itself, a diagnosis. The lawyer must still ask the hard questions: what is the evidence, what is the applicable collective instrument, what is the procedural

The New Era of Labor Compliance in Brazil: How the PGR and NR-01 Transformed Corporate Mental Health Management

Brazil has a comprehensive regulatory framework for protecting the health and safety of its workforce. These rules are created and updated by the Ministry of Labor and Employment to prevent occupational accidents and illnesses. Known as Regulatory Standards (Normas Regulamentadoras – NRs), compliance is mandatory for any company employing workers under formal employment contracts (carteira assinada). To use a game analogy, the NRs serve as the game’s rulebook, where the core objective is to protect workers’ health and safety. There are currently 38 active NRs covering a wide range of topics, such as safety standards for working at heights (NR-35), health services guidelines (NR-32), sanitary and comfort conditions in workplaces (NR-24), and protocols for handling explosives (NR-19), among others. Recently, a highly significant shift occurred within this regulatory architecture. NR-01, which establishes the foundation for the entire occupational health and safety system in Brazil, outlines the general provisions, scope of application, definitions common to all NRs, and the guidelines and requirements for occupational risk management and preventive measures. The Scope of Occupational Risk Management (GRO) Recognizing the growing importance and complexity of mental well-being in workers’ daily lives, the updated NR-01 now explicitly integrates psychosocial risk factors into the scope of Occupational Risk Management (Gerenciamento de Riscos Ocupacionais – GRO). The GRO establishes a systematic framework for hazard identification, risk assessment, and control. It must be seamlessly integrated with other medical initiatives (such as the Occupational Health Medical Control Program – NR-07), accident analysis, and emergency preparedness. The primary objective of the GRO is the prevention and mitigation of workplace risks, and NR-01 mandates its implementation across all of an organization’s business establishments. The core workflows of the GRO must be formalized into an Occupational Risk Management Program (Programa de Gerenciamento de Riscos – PGR), which is defined as: “A coordinated set of actions by the organization designed to achieve occupational risk prevention and management objectives, formally documented.” — Subitem 1.5.3.1.1 of NR-01 Under these regulations, implementing a PGR is mandatory for each business location and must cover all activities performed there. At a minimum, it must include an occupational risk inventory, an action plan, and the criteria used for risk assessment within the GRO/PGR framework. To ensure full compliance with NR-01, organizations must also document additional supporting records, including: Workplace accident and illness analysis reports (subitem 1.5.5.5.2); Implementation logs for preventive measures (subitem 1.5.5.3.1); Planned monitoring records for the performance of preventive measures (subitem 1.5.5.3.2); Evidence of simulated emergency response drills (subitem 1.5.6.3.1); Training and capacity-building records as prescribed by the NRs. The operational flow of this documentation can be simplified into a continuous cycle: Identify risks – Assess – Control – Monitor. The Transition from PPRA to PGR: Integrating Ergonomics and Psychosocial Factors The most substantial update lies in the scope of the risk assessment. The former PPRA (the program replaced by the PGR) was strictly limited to environmental hazards (physical, chemical, and biological risks). However, under the updated NR-01, the PGR must also encompass risks stemming from ergonomic factors, which explicitly include work-related psychosocial risk factors. This regulatory shift is milestone-heavy because it legally recognizes the central role of mental health in overall worker well-being. This alignment is further reinforced by NR-17, which embeds psychosocial risk factors directly into ergonomic management—the central focus of that standard. To achieve NR-17’s objective of adapting working conditions to the psychophysiological characteristics of workers, the standard mandates two complementary methodologies: Preliminary Ergonomic Evaluation (Avaliação Ergonômica Preliminar – AEP): which is mandatory; Ergonomic Workplace Analysis (Análise Ergonômica do Trabalho – AET): required only under specific operational circumstances. Through the AEP, risk assessments for ergonomic and psychosocial hazards can be conducted using qualitative and participatory approaches, integrating them directly into the PGR’s baseline hazard identification process. This implementation must always be multidisciplinary and multi-professional. Crucially, workers must have a voice in this process. To facilitate open dialogue, companies must cultivate an environment of psychological safety and conduct surveys anonymously, ensuring employees do not feel intimidated by fears of exposure or reprisal. The Organizational Roots of Psychosocial Risks It is vital to emphasize that the root source of psychosocial risks does not reside within the individual worker, but rather within the organization of work itself. This includes deficiencies in task design, personnel management, and organizational workflows. Left unmanaged, these systemic issues trigger severe psychological, physical, and social health consequences, including workplace stress, burnout, Work-Related Musculoskeletal Disorders (WMSDs/DORT), and depression. Consequently, identifying psychosocial risks requires evaluating work organization—meaning how tasks and activities are structured, distributed, and coordinated within the environment. When evaluating these factors, organizations must analyze which elements of the work activity act as stressors with the potential to cause injury or health deterioration. The focus is not on diagnosing individual symptoms or capturing subjective “moods,” but on auditing objective working conditions, identifying operational stressors, and evaluating environmental and systemic flaws. Once psychosocial risks are identified, companies must assess and classify them. The risk level is calculated by combining the severity of potential injuries or health impairments with the probability of occurrence, as outlined in subitem 1.5.4.4.2 of NR-01. With the diagnosis complete, the necessary preventive measures must be integrated directly into the PGR Action Plan. The Current Landscape: Compliance, Sustainability, and the Future of Governance The urgency of this landscape—which was already alarming in 2021 when World Health Organization (WHO) data indicated that 359 million people globally suffered from anxiety disorders—has consolidated over the past five years as one of the defining corporate governance challenges of our time. In 2026, with the maturation of hybrid working models and accelerated technological transformation, it has become undeniable that mental well-being can no longer be treated as a purely individual responsibility or an auxiliary corporate benefit. It is, fundamentally, an outcome of organizational design. Therefore, the inclusion of psychosocial risks within the PGR and NR-17 represents far more than a bureaucratic milestone; it is a definitive turning point for corporate compliance and ESG sustainability. By shifting the regulatory focus away from employee symptoms and toward

The Taxation Omnibus and The Return of Competitiveness: What The EU’s Simplification Turn Asks of Anti-Abuse

When the European Commission adopted its Tax Simplification Package on 24 June 2026, the presentation was almost entirely about relief: some eight billion euros a year in lower compliance costs, a lighter withholding regime, fewer overlapping calculations, a research allowance to draw investment to the continent. The headline was decluttering, and on that measure the package delivers. Yet read against the decade that produced it, the Omnibus is less a housekeeping exercise than a change of direction. For most of the post-BEPS period the centre of gravity in EU direct tax was anti-abuse, as successive directives layered controlled-foreign-company rules, interest limitations, hybrid-mismatch provisions and a general anti-abuse rule onto national systems, each meant to close a gap. The Omnibus reverses the reflex: its animating question is no longer how to prevent leakage but how to keep capital, financing and research inside the Single Market, and that reversal is where the interesting problems sit. What The Package Actually Does The Simplification Package comprises two instruments: a draft Omnibus Directive amending six tax directives, and a recast of the Directive on Administrative Cooperation consolidating the DAC framework into a single text. Four measures carry most of the weight for corporate groups. The most consequential is the treatment of withholding taxes. The Omnibus would exempt cross-border payments of dividends, interest and royalties between EU companies from source taxation, attacking the conditions, not merely the rate. The minimum-holding thresholds that currently gate the Interest and Royalties Directive and the Parent-Subsidiary Directive would go, as would the prior-authorisation procedures used to verify entitlement before payment; a self-assessment model would replace them, with the FASTER refund mechanism as a backstop where eligibility cannot be confirmed upfront. The Parent-Subsidiary Directive would also extend to pension institutions. On the Commission’s own figures these account for the bulk of the savings, which tells you where the package’s centre really lies. The second measure reshapes the interest limitation rule. The thirty-percent-of-EBITDA cap becomes uniform and mandatory, the three-million-euro de minimis safe harbour becomes a floor rather than a ceiling, indexed to inflation so that it can only rise, and genuine third-party and market financing is carved out where the borrowing funds the taxpayer’s own activities rather than on-lending within the group. Optional elements that fragmented implementation, the group-escape and carry-forward mechanisms, become mandatory. The defence sector is temporarily excluded, as much a political signal as a tax measure. A uniform mandatory cap also overrides deliberate national choices: the Netherlands, among others, had set its threshold below thirty percent, and would have to loosen a rule it chose to keep tight. The third measure is the one practitioners should watch most closely, because it is where simplification and sovereignty collide. The Omnibus removes the overlap between the ATAD controlled-foreign-company rules and the Pillar Two global minimum tax by exempting groups within scope of Pillar Two from the CFC regime altogether. The logic is clean: a group already computing top-up tax on low-taxed subsidiaries should not also run a parallel CFC calculation on the same income, a duplication the Commission puts at around a hundred and sixty million euros a year. The two CFC models then collapse into one, the passive-income approach made mandatory and divergent national variants barred. The fourth measure points in a different direction entirely. A new research-and-development allowance, grafted onto the ATAD, would give full and immediate expensing of qualifying tangible R&D assets as a binding minimum standard across the Union. That an anti-avoidance directive should now house an investment incentive captures the whole shift: the instrument built to protect the base is being asked to grow it. Running in parallel, the DAC recast narrows DAC6, carving out Pillar Two groups from cross-border-arrangement reporting and deleting hallmarks judged to generate more noise than signal. The Problem Underneath The Relief None of this is straightforwardly deregulatory, nor a retreat from anti-abuse. The general anti-abuse rule is not weakened; it is extended, reaching beyond corporate tax to withholding taxes and to the Pillar Two top-up taxes themselves, closing an uncertainty lingering since the minimum tax arrived. A subject-to-tax safeguard guards against the withholding exemptions producing double non-taxation where the recipient is taxed nominally at zero. The architecture of protection remains; what changes is its calibration. The Commission’s wager is that several anti-abuse rules were addressing risks that Pillar Two now covers, so that maintaining both is not prudence but duplication. Yet the same package that widens the GAAR narrows anti-abuse elsewhere. The imported mismatch provisions of ATAD, which denied a deduction where a payment financed a hybrid mismatch further down the chain, are removed outright, the Commission judging them too complex and poorly targeted. Unlike the CFC change, no other instrument steps into the gap: the rule goes not because something else does its work, but because it was hard to apply. That asymmetry, anti-abuse expanding on one front and contracting on another within a single directive, is the clearest sign that usability, not protection, is now the organising principle. That wager is defensible, but it is a wager, and it exposes the deeper tension in the package. Simplification in EU direct tax is not a technical act: every rule the Omnibus makes uniform is a rule a Member State can no longer tune to its own base, and every carve-out is revenue foregone somewhere. The CFC exemption is the clearest case. Removing the overlap with Pillar Two sounds unanswerable until one remembers that Pillar Two, by design, raises little revenue in many jurisdictions, while CFC charges can raise real amounts. States that built their regimes on the transactional Model B, Ireland, Malta and the Netherlands among them, are asked to abandon it for a mandatory passive-income model and to surrender a working revenue tool on the theory that a lower-yielding one has superseded it. It is no surprise the CFC changes are expected to be among the most contested at Council. This is the structural difficulty the Omnibus cannot draft its way around. Direct tax measures require unanimity

Organised by

ClickAway Creators LLP
(Co-organised by CAC Media & Events Inc., Canada)

Association & Speakership – Gagan

gagan@clickawaycreators.com

+1 778 907 9496

Sponsorship & Exhibition – Kritika

kritika@clickawaycreators.com

+1 (778) 323-1904

Global Legal Honour and Delegate passes

ajay@Clickawaycreators.com

+1 778 907 9496

© 2026 by ClickAway Creators LLP. All Rights Reserved.

Privacy Policy      Terms of Service      Cookie Policy

Thank You!

We have received your details. Please check your inbox shortly for complete information regarding CLE credits.

Sponsor Enquiry

Join the global stage for legal innovation and leadership.